web-ctf

Installation
SKILL.md

Web CTF

Goal: solve web-application CTF tasks with professional methodology, curated high-signal references, and reproducible evidence.

When this skill applies

  • HTTP apps, APIs, browser clients, templates, auth flows, file uploads, SSRF, XSS, SQLi, SSTI, XXE, deserialization, request smuggling, GraphQL/WebSocket APIs, or prototype pollution
  • tasks requiring endpoint mapping, parameter discovery, exploit chaining, or stateful session testing

Operating model

  1. Classify the dominant artifact, primitive, or objective.
  2. Load the closest offensive-techniques methodology before selecting tools.
  3. Load the closest curated reference for the dominant primitive before touching deep topic banks.
  4. Use sql-injection.md as the deep bank when the focused SQLi reference is too shallow for the current edge case.
  5. Choose the smallest tool chain that can produce a validation signal.
  6. Record the exact proof path and stop once the objective is reproducible.

Technique integration

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
web-ctf — aeondave/malskill